Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m4rm-x2rr-357w

Опубликовано: 06 мар. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.3

Описание

Jenkins Bitbucket Branch Source Plugin has incorrect trust policy behavior for pull requests

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

Пакеты

Наименование

org.jenkins-ci.plugins:cloudbees-bitbucket-branch-source

maven
Затронутые версииВерсия исправления

< 871.v28d74e8b4226

871.v28d74e8b_4226

EPSS

Процентиль: 9%
0.00033
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 6.3
redhat
почти 2 года назад

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

CVSS3: 6.3
nvd
почти 2 года назад

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.

EPSS

Процентиль: 9%
0.00033
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-281